--- - name: Configure MikroTik switches (day-2, key auth) hosts: mikrotik gather_facts: false # Operator passwords (users.yml) are vaulted; group_vars/mikrotik.vault.yml does not # match the group-name convention, so load it explicitly. Decrypted via the makerfloss # vault id in ansible.cfg — no --ask-vault-pass needed. vars_files: - group_vars/mikrotik.vault.yml roles: - makerfloss.mikrotik_switch